Use-after-free in Linux kernel - CVE-2026-89899
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to a use-after-free race condition in cec_transmit_msg_fh in the CEC subsystem when a blocking transmit wait is interrupted by a signal. A local user can interrupt a blocking transmit wait with a signal to compromise confidentiality, integrity, and availability.